exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 277 discussion

Actual exam question from CompTIA's CS0-002
Question #: 277
Topic #: 1
[All CS0-002 Questions]

A security analyst is reviewing the network security monitoring logs listed below:

  • A. 10.1.1.128 sent potential malicious traffic to the web server
  • B. 10.1.1.128 sent malicious requests, and the alert is a false positive
  • C. 10.1.1.129 successfully exploited a vulnerability on the web server
  • D. 10.1.1.129 sent potential malicious requests to the web server
  • E. 10.1.1.129 sent non-malicious requests, and the alert is a false positive
  • F. 10.1.1.130 can potentially obtain information about the PHP version
Show Suggested Answer Hide Answer
Suggested Answer: DF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
db97
Highly Voted 2 years, 2 months ago
D & F are correct answers here. D, because PhpStudy is a documented/known backdoor so the source IP attempted a malicious connection. References: https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/phpstudy_backdoor_rce https://www.fortiguard.com/encyclopedia/ips/48804 F, because the phpinfo can provide access about the PHP version for sure.
upvoted 8 times
2Fish
2 years, 1 month ago
Agreed. I was not sure until I researched, as well as using your links. Thanks for the comment.
upvoted 1 times
...
...
absabs
Most Recent 2 years, 2 months ago
Selected Answer: DF
Already D is correct and 130 send php info access packet.
upvoted 4 times
...
gnnggnnggnng
2 years, 2 months ago
Selected Answer: D
Based on the logs, the following events were recorded: "GPL WEB SERVER robots.txt access" from 10.1.1.128 to 10.0.0.10 "ET WEB SPECIFIC APPS PHPStudy Remote Code Execution Backdoor" from 10.1.1.129 to 10.0.0.10 "ET WEB SERVER MEB-PHP phpinfo access" from 10.1.1.130 to 10.0.0.10 "GPL WEB SERVER 403 Forbidden" from 10.0.0.10 to 10.1.1.129 Based on this information, I selected option D as the correct answer, which states "10.1.1.129 sent potential malicious requests to the web server". The logs indicate that the IP address 10.1.1.129 is involved in a remote code execution backdoor, which is a clear indication of malicious activity. The "403 Forbidden" response from the web server suggests that the request from 10.1.1.129 was blocked.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago